Thursday, 2020-03-05

*** dklyle has joined #openstack-infra00:02
*** yamamoto has joined #openstack-infra00:02
corvusw/win 1200:04
corvusgrr00:04
openstackgerritClark Boylan proposed opendev/puppet-httpd master: Define params::ssl_path for vhost::proxy  https://review.opendev.org/71136500:05
clarkbmordred: ^ also that fixes a puppet error on paste00:05
openstackgerritMerged openstack/hacking master: [ussuri][goal] Drop python 2.7 support and testing  https://review.opendev.org/70551400:07
*** slaweq has joined #openstack-infra00:11
ianwi'm thinking i'll emergency file and shutdown files02.openstack.org and static-old.openstack.org ... nobody should notice anything but they'll just be a restart away.  we can merge the inventory/puppet removal next week and then that will be it00:12
clarkb++00:13
ianw#status log files02.openstack.org & static-old.openstack.org hosts in emergency file and shutdown for retirement.  old system-config configuration to be removed next week00:16
openstackstatusianw: finished logging00:16
mordredclarkb: oh right00:17
*** dklyle has quit IRC00:19
*** toabctl has quit IRC00:19
*** Tengu has quit IRC00:20
*** Tengu has joined #openstack-infra00:22
*** toabctl has joined #openstack-infra00:22
*** dklyle has joined #openstack-infra00:22
ianwmordred: do you want to take a look at https://review.opendev.org/#/c/677903/ to make haproxy a more generic role, even though we didn't go with it for redirects?  i still think it probably has value for future work00:26
*** slaweq has quit IRC00:27
ianw#status log removed project.gittest volume (https://storyboard.openstack.org/#!/story/2006598 task #38841)00:27
openstackstatusianw: finished logging00:27
*** mattw4 has quit IRC00:29
*** igordc has quit IRC00:33
ianw#status log removed logs.openstack.org and logs-dev.openstack.org CNAMES as there is nothing to serve any more ((https://storyboard.openstack.org/#!/story/2006598 task#37735)00:34
openstackstatusianw: finished logging00:34
openstackgerritIan Wienand proposed opendev/system-config master: letsencrypt: Register email with accounts  https://review.opendev.org/71113300:52
openstackgerritIan Wienand proposed opendev/system-config master: letsencrypt: add note on manual refresh of certificates  https://review.opendev.org/71113700:52
openstackgerritIan Wienand proposed opendev/system-config master: ansible-lint : disable 503  https://review.opendev.org/71114900:52
*** igordc has joined #openstack-infra00:53
*** happyhemant has quit IRC00:55
ianwdoes anyone know if collect-container-logs is where we collect podman logs too?00:56
ianwoohhh, yes ok it is, i see00:57
ianwi think that podman-compose does not accurately report errors00:58
clarkbianw: yup it iterates through podman and docker commands for grabbing container logs01:08
clarkbif the errors are compose side its probably the wrong layer to request logs for01:09
clarkbmordred: https://zuul.opendev.org/t/openstack/build/3efc22c4968b4767b07cae159ee4e318/log/applytest/puppetapplytest08.final.out.FAILED#121 I think it may not be the right parameter there?01:10
clarkbmordred: I think we want ensure => latest then something like revision => 'sha"01:10
*** gyee has quit IRC01:10
*** slaweq has joined #openstack-infra01:11
openstackgerritClark Boylan proposed opendev/puppet-lodgeit master: Allow pinning the lodgeit version  https://review.opendev.org/71134401:13
clarkbmordred: ^ I think that may make it happy01:13
*** slaweq has quit IRC01:16
openstackgerritIan Wienand proposed opendev/system-config master: letsencrypt: Register email with accounts  https://review.opendev.org/71113301:26
openstackgerritIan Wienand proposed opendev/system-config master: letsencrypt: add note on manual refresh of certificates  https://review.opendev.org/71113701:26
openstackgerritIan Wienand proposed opendev/system-config master: ansible-lint : disable 503  https://review.opendev.org/71114901:26
openstackgerritTristan Cacqueray proposed zuul/zuul master: Implement zookeeper-auth  https://review.opendev.org/61915601:31
*** lbragstad_ has joined #openstack-infra01:34
openstackgerritIan Wienand proposed opendev/system-config master: [wip] deploy nodepool-builder container  https://review.opendev.org/71089101:35
*** lbragstad has quit IRC01:36
*** nhicher has quit IRC01:38
*** nhicher has joined #openstack-infra01:38
*** tkajinam has quit IRC01:49
*** tkajinam has joined #openstack-infra01:50
ianwclarkb: is this expected? 2020-03-05 02:02:24.187543 | localhost | Provider: airship-kna102:04
clarkbianw: the cloud you mean? ya02:06
clarkbwe carved out a small chunk of it for general use (to ensure things are generally working)02:06
*** igordc has quit IRC02:07
ianwahh, ok :)02:08
*** slaweq has joined #openstack-infra02:11
*** slaweq has quit IRC02:16
*** Goneri has quit IRC02:24
*** xinranwang has joined #openstack-infra02:42
*** psachin has joined #openstack-infra02:50
*** roman_g has quit IRC02:53
*** raukadah is now known as chandankumar03:02
*** lbragstad_ has quit IRC03:09
*** slaweq has joined #openstack-infra03:11
*** nicolasbock has joined #openstack-infra03:12
*** slaweq has quit IRC03:16
openstackgerritIan Wienand proposed opendev/system-config master: [wip] deploy nodepool-builder container  https://review.opendev.org/71089103:34
*** larainema has joined #openstack-infra03:44
*** apetrich has quit IRC04:00
*** udesale has joined #openstack-infra04:09
*** slaweq has joined #openstack-infra04:11
*** slaweq has quit IRC04:16
*** rlandy|bbl is now known as rlandy04:29
*** nicolasbock has quit IRC04:30
*** rlandy has quit IRC04:53
*** ykarel|away is now known as ykarel04:55
*** zxiiro has joined #openstack-infra05:00
*** rkukura has quit IRC05:06
*** rkukura has joined #openstack-infra05:07
*** slaweq has joined #openstack-infra05:11
openstackgerritIan Wienand proposed opendev/system-config master: Collect docker logs as root  https://review.opendev.org/71088505:15
*** LiangFang has joined #openstack-infra05:19
*** udesale has quit IRC05:31
openstackgerritIan Wienand proposed opendev/system-config master: [wip] deploy nodepool-builder container  https://review.opendev.org/71089105:32
*** evrardjp has quit IRC05:35
*** evrardjp has joined #openstack-infra05:35
LiangFanghi, I want to create a repo under openstack namespace, like openstack/devstack-plugin-open-cas05:38
*** slaweq has quit IRC05:38
LiangFangcould anyone guide me how to create the repo? thanks05:38
*** udesale has joined #openstack-infra05:39
*** factor has quit IRC05:47
*** factor has joined #openstack-infra05:48
AJaegerLiangFang: we have a manual for that, see https://docs.openstack.org/infra/manual/creators.html06:02
AJaegerinfra-root, I cannot connect to zuul-ci.org, I get connection timeouts ;(06:02
AJaegerLiangFang: Not that for the openstack namespace, the repo needs to be part of an official team.06:03
LiangFangAJaeger: thanks06:14
LiangFangAJaeger: I still cannot find the method to create repo. This page shows how to choose the project name and how to add owner, something like that.06:17
LiangFangAJaeger: Could you please paste the words that shows how to create repo here? thanks06:18
*** weshay|ruck has quit IRC06:36
*** weshay has joined #openstack-infra06:36
*** weshay has quit IRC06:40
*** weshay has joined #openstack-infra06:40
*** otherwiseguy has quit IRC06:41
*** otherwiseguy has joined #openstack-infra06:42
*** threestrands has quit IRC06:48
*** dannins has joined #openstack-infra06:59
*** ccamacho has quit IRC07:02
*** weshay has quit IRC07:13
*** weshay_ has joined #openstack-infra07:16
*** jcapitao_off has joined #openstack-infra07:20
*** matt_kosut has quit IRC07:21
*** jcapitao_off is now known as jcapitao07:22
AJaegerLiangFang: the whole document is a howto on how to create one using our tools and review process. To create one, you basically need to submit a review to gerrit and the document explains what to be aware of. There's no shortcut.07:29
AJaegerLiangFang: There's no single button to create a repo, it's a normal review step in gerrit07:30
openstackgerritAndreas Jaeger proposed openstack/infra-manual master: List other Contributor Guides  https://review.opendev.org/71139307:32
*** otherwiseguy has quit IRC07:34
*** weshay_ has quit IRC07:34
*** weshay_ has joined #openstack-infra07:34
*** matt_kosut has joined #openstack-infra07:35
*** xinranwang has quit IRC07:35
*** otherwiseguy has joined #openstack-infra07:35
*** ykarel is now known as ykarel|lunch07:35
*** matt_kosut has quit IRC07:37
*** matt_kosut has joined #openstack-infra07:37
*** weshay_ has quit IRC07:39
*** haleyb|away has quit IRC07:39
*** otherwiseguy has quit IRC07:40
openstackgerritBenedikt Löffler proposed zuul/zuul master: Fix override variables in zuul_return  https://review.opendev.org/71100207:43
*** tetsuro has joined #openstack-infra07:44
*** happyhemant has joined #openstack-infra07:50
*** tesseract has joined #openstack-infra07:52
*** otherwiseguy has joined #openstack-infra07:56
*** weshay_ has joined #openstack-infra07:56
*** iurygregory has joined #openstack-infra07:56
larainemahi infra team,  I have a question related the check pipline py27 job to py36 job,  we have a project https://opendev.org/x/networking-zvm, we want to drop the py27 job and enable py36 job in check pipline, how I can do it? just change the .zuul.yaml?  but i didn't find the origin py27 job in .zuul.yaml07:57
AJaegerlarainema: https://opendev.org/openstack/project-config/src/branch/master/zuul.d/projects.yaml#L5850 is the job07:59
AJaegerlarainema: Remove that entry and add the jobs in-tree instead.07:59
larainemathanks AJaeger, just to confirm, i should add the jobs in .zuul.yaml under networking-zvm repo or add it still in project-config08:01
fricklerAJaeger: zuul-ci.org points to files02, which ianw shut down. is that domain still used for anything? we probably missed moving it to the new setup, then08:04
LiangFangAJaeger: thanks, in order to create a repo, which repo should I submit review agaist? openstack / project-config?08:06
*** ccamacho has joined #openstack-infra08:11
AJaegerlarainema: add the job in .zuul.yaml in your repo, and remove the jobs from project-config08:12
AJaegerfrickler: isn't zuul-ci.org the central Zuul landing page?08:13
larainemathanks AJaeger08:13
AJaegerLiangFang: yes, that's the one08:14
AJaegerfrickler: so, yes, we need to fix zuul-ci. Hope it's the only place broken.08:14
LiangFangAJaeger: thank you08:15
AJaegerfrickler, ianw, is it just the wrong DNS entry for zuul-ci.org? Or is more needed?08:15
*** harlowja has quit IRC08:15
*** tkajinam has quit IRC08:16
AJaegerSeems only DNS entry wrong, if I add "23.253.245.150  zuul-ci.org" to /etc/hosts, I can connect to zuul-ci.org08:17
AJaegerianw: what needs to be done to chane the DNS entry?08:21
*** ralonsoh has joined #openstack-infra08:22
*** weshay_ has quit IRC08:24
*** weshay has joined #openstack-infra08:25
*** jpena|off is now known as jpena08:26
*** ykarel|lunch is now known as ykarel08:32
openstackgerritDong Ma proposed openstack/project-config master: Remove networking-zvm entry  https://review.opendev.org/71139908:33
openstackgerritFelix Edel proposed zuul/zuul master: Allow check runs to be configured as required status in pipeline config  https://review.opendev.org/71124108:34
*** pgaxatte has joined #openstack-infra08:36
*** matt_kosut has quit IRC08:44
*** amoralej|off is now known as amoralej08:45
openstackgerritFelix Edel proposed zuul/zuul master: Allow check runs to be configured as required status in pipeline config  https://review.opendev.org/71124108:45
*** rpittau|afk is now known as rpittau08:46
*** yamamoto has quit IRC08:47
*** ysastri has joined #openstack-infra08:47
*** dchen has quit IRC08:48
*** hashar has joined #openstack-infra08:49
*** hashar_ has joined #openstack-infra08:50
ianwAJaeger: oh doh, we can fix that.  i think i have a change out08:52
*** hashar__ has joined #openstack-infra08:53
*** hashar has quit IRC08:54
*** hashar_ has quit IRC08:55
*** andreykurilin has quit IRC08:56
openstackgerritIan Wienand proposed opendev/zone-zuul-ci.org master: Use static.opendev.org  https://review.opendev.org/71140308:56
*** andreykurilin has joined #openstack-infra08:56
*** matt_kosut has joined #openstack-infra08:58
*** matt_kosut has quit IRC08:59
*** matt_kos_ has joined #openstack-infra08:59
*** verdurin has quit IRC09:00
openstackgerritMerged opendev/zone-zuul-ci.org master: git.zuul-ci.org : point to static.opendev.org  https://review.opendev.org/71014209:02
AJaegerthanks, ianw !09:02
*** hashar__ is now known as hashar09:03
*** yamamoto has joined #openstack-infra09:03
*** yamamoto has quit IRC09:04
*** matt_kos_ has quit IRC09:04
*** yamamoto has joined #openstack-infra09:04
fricklerianw: reviewing your DNS fix I noticed that there is no rDNS for the new static server, is this also still pending as a review somewhere?09:05
openstackgerritMerged opendev/zone-zuul-ci.org master: Use static.opendev.org  https://review.opendev.org/71140309:06
*** zxiiro has quit IRC09:07
*** mwhahaha has quit IRC09:07
*** gagehugo has quit IRC09:07
*** Shrews has quit IRC09:07
*** dayou has quit IRC09:07
*** rosmaita has quit IRC09:07
*** auristor has quit IRC09:08
*** stevebaker has quit IRC09:08
*** iokiwi has quit IRC09:08
*** tinwood has quit IRC09:08
*** irclogbot_0 has quit IRC09:08
*** portdirect has quit IRC09:08
*** StevenK has quit IRC09:08
*** jaicaa has quit IRC09:08
ianwfrickler: hrm, i might be able to do that via the rax interface09:08
ianwfrickler: ok, added via the webui09:10
fricklerianw: cool, though to be 100% correct we'd maybe rather want static01 as hostname?09:11
*** verdurin has joined #openstack-infra09:12
ianwsure, seems reasonable, updated09:12
*** Lucas_Gray has joined #openstack-infra09:13
*** matt_kosut has joined #openstack-infra09:13
*** matt_kosut has quit IRC09:18
openstackgerritFelix Edel proposed zuul/zuul master: Don't rely on report-build-page when building the buildset result url  https://review.opendev.org/71140609:19
openstackgerritLuigi Toscano proposed openstack/cookiecutter master: Fix links formatting for the contributing documentation  https://review.opendev.org/71140709:22
openstackgerritIan Wienand proposed opendev/system-config master: [wip] deploy nodepool-builder container  https://review.opendev.org/71089109:23
*** apetrich has joined #openstack-infra09:24
*** gfidente|afk is now known as gfidente09:25
*** tosky has joined #openstack-infra09:25
ianwAJaeger/frickler: i'm seeing zuulci / zuul-ci ok now, do you agree?09:28
*** tetsuro has quit IRC09:29
AJaegerianw: here as well - thanks09:31
ianwsorry about that ... i'm out for this evening, ttyl09:32
AJaegerianw: enjoy!09:34
*** sshnaidm|afk is now known as sshnaidm09:37
openstackgerritAndreas Jaeger proposed openstack/infra-manual master: OpenDev Update for Creator's Guide  https://review.opendev.org/71141109:40
openstackgerritAndreas Jaeger proposed openstack/project-config master: Move diskimage-builder to #opendev  https://review.opendev.org/71141209:43
AJaegerfrickler: here's the one move you suggested, any others, best push yourself ^09:43
*** zxiiro has joined #openstack-infra09:43
*** mwhahaha has joined #openstack-infra09:43
*** gagehugo has joined #openstack-infra09:43
*** Shrews has joined #openstack-infra09:43
*** dayou has joined #openstack-infra09:43
*** rosmaita has joined #openstack-infra09:43
*** auristor has joined #openstack-infra09:43
*** stevebaker has joined #openstack-infra09:43
*** iokiwi has joined #openstack-infra09:43
*** tinwood has joined #openstack-infra09:43
*** irclogbot_0 has joined #openstack-infra09:43
*** portdirect has joined #openstack-infra09:43
*** StevenK has joined #openstack-infra09:43
*** jaicaa has joined #openstack-infra09:43
*** openstackstatus has quit IRC09:45
fricklerAJaeger: thanks, well we'll have to wait for the big cleanup to be merged first, I guess09:59
openstackgerritValentina Krasnobaeva proposed openstack/project-config master: Update jobs for  networking-6wind  https://review.opendev.org/71141910:01
*** ociuhandu has joined #openstack-infra10:03
AJaegerfrickler: or make it a followup to 10610:05
*** roman_g has joined #openstack-infra10:10
*** ociuhandu has quit IRC10:13
*** derekh has joined #openstack-infra10:13
*** Lucas_Gray has quit IRC10:14
*** Lucas_Gray has joined #openstack-infra10:15
*** jcapitao has quit IRC10:20
*** jcapitao has joined #openstack-infra10:21
*** psachin has quit IRC10:23
*** dtantsur|afk is now known as dtantsur10:24
*** gshippey has joined #openstack-infra10:24
*** jcapitao has quit IRC10:32
*** jcapitao has joined #openstack-infra10:33
*** ociuhandu has joined #openstack-infra10:33
*** ociuhandu has quit IRC10:38
*** hashar has quit IRC10:38
brtknrHi all, is there a way to access GPU enabled VMs via Zuu?10:47
brtknrHi all, is there a way to access GPU enabled VMs via Zuul?10:47
*** jaicaa has quit IRC10:48
*** udesale has quit IRC10:49
*** Lucas_Gray has quit IRC10:49
*** Lucas_Gray has joined #openstack-infra10:51
*** jaicaa has joined #openstack-infra10:51
*** matt_kosut has joined #openstack-infra10:54
*** Lucas_Gray has quit IRC10:58
*** Lucas_Gray has joined #openstack-infra10:58
openstackgerritSorin Sbarnea proposed zuul/zuul-jobs master: Tests bindep role on all-platforms  https://review.opendev.org/70870411:00
*** Lucas_Gray has quit IRC11:06
*** ysastri has quit IRC11:09
openstackgerritSorin Sbarnea proposed zuul/zuul-jobs master: Improve ensure-tox role  https://review.opendev.org/70864211:13
openstackgerritDmitriy Rabotyagov (noonedeadpunk) proposed opendev/lodgeit master: Removes unnecessary utf-8 encoding  https://review.opendev.org/41874811:17
openstackgerritSorin Sbarnea proposed opendev/gear master: tox: enable extra python versions  https://review.opendev.org/70341811:18
*** slaweq has joined #openstack-infra11:18
*** ociuhandu has joined #openstack-infra11:20
*** rpittau is now known as rpittau|bbl11:27
*** Lucas_Gray has joined #openstack-infra11:27
*** tesseract-RH has joined #openstack-infra11:40
*** tesseract has quit IRC11:43
*** nicolasbock has joined #openstack-infra11:47
*** ociuhandu has quit IRC11:47
*** zxiiro has quit IRC11:48
*** ociuhandu has joined #openstack-infra11:48
*** ijw_ has quit IRC11:54
*** jcapitao is now known as jcapitao_lunch11:54
*** ijw has joined #openstack-infra11:55
*** rlandy has joined #openstack-infra12:02
*** tetsuro has joined #openstack-infra12:03
mgoddardI think ansible 2.9.6 has broken openstack modules12:05
mgoddardSeeing this sort of thing everywhere:12:05
mgoddardhttps://b317bafa0db642d61e9b-babe6b68bec526aecbe80deed799da2b.ssl.cf2.rackcdn.com/711295/3/check/kolla-ansible-centos-source/b02cb5e/primary/logs/ansible/deploy12:05
mgoddard(also on py3)12:05
*** tetsuro has quit IRC12:06
*** amoralej is now known as amoralej|lunch12:06
openstackgerritBenedikt Löffler proposed zuul/zuul master: Fix override variables in zuul_return  https://review.opendev.org/71100212:07
*** jpena is now known as jpena|lunch12:09
*** dpawlik has quit IRC12:14
*** dpawlik has joined #openstack-infra12:15
*** slaweq has quit IRC12:18
*** jcapitao_lunch has quit IRC12:19
*** jcapitao_lunch has joined #openstack-infra12:21
*** dpawlik has quit IRC12:22
*** dpawlik has joined #openstack-infra12:36
*** rkukura has quit IRC12:45
*** rkukura has joined #openstack-infra12:46
openstackgerritEric Fried proposed opendev/gerritbot master: Refactor ChannelConfig with channels_for  https://review.opendev.org/54546912:51
openstackgerritBenedikt Löffler proposed zuul/zuul master: Fix override variables in zuul_return  https://review.opendev.org/71100212:51
*** Lucas_Gray has quit IRC12:55
openstackgerritBenedikt Löffler proposed zuul/zuul master: Fix override variables in zuul_return  https://review.opendev.org/71100212:56
*** ociuhandu has quit IRC13:01
*** ahosam has joined #openstack-infra13:01
*** yamamoto has quit IRC13:03
*** dave-mccowan has joined #openstack-infra13:10
*** rh-jelabarre has joined #openstack-infra13:13
*** udesale has joined #openstack-infra13:14
*** jcapitao_lunch is now known as jcapitao13:15
*** jamesmcarthur has joined #openstack-infra13:20
*** rh-jelabarre has quit IRC13:21
*** rh-jelabarre has joined #openstack-infra13:21
*** takamatsu has joined #openstack-infra13:22
*** hashar has joined #openstack-infra13:22
*** ociuhandu has joined #openstack-infra13:28
*** matt_kosut has quit IRC13:31
*** ociuhandu has quit IRC13:31
*** ociuhandu has joined #openstack-infra13:31
*** matt_kosut has joined #openstack-infra13:34
*** jamesmcarthur has quit IRC13:38
*** matt_kosut has quit IRC13:39
*** jamesmcarthur has joined #openstack-infra13:40
*** yamamoto has joined #openstack-infra13:40
*** cgoncalves has quit IRC13:41
*** cgoncalves has joined #openstack-infra13:45
*** jamesmcarthur has quit IRC13:45
*** rpittau|bbl is now known as rpittau13:45
*** jcoufal has joined #openstack-infra13:54
*** jcoufal has quit IRC13:54
*** yamamoto has quit IRC13:55
*** jcoufal has joined #openstack-infra13:55
*** yamamoto has joined #openstack-infra13:57
*** yamamoto has quit IRC14:05
*** yamamoto has joined #openstack-infra14:05
*** yamamoto has quit IRC14:05
*** jamesmcarthur has joined #openstack-infra14:09
*** lbragstad has joined #openstack-infra14:13
*** auristor has quit IRC14:14
*** jamesmcarthur has quit IRC14:15
*** matt_kosut has joined #openstack-infra14:17
*** auristor has joined #openstack-infra14:18
*** matt_kosut has quit IRC14:22
*** ykarel is now known as ykarel|away14:27
*** jpena|lunch is now known as jpena14:29
*** amoralej|lunch is now known as amoralej14:31
*** Goneri has joined #openstack-infra14:31
*** hashar has quit IRC14:32
*** hashar has joined #openstack-infra14:32
*** ociuhandu has quit IRC14:33
*** ociuhandu has joined #openstack-infra14:33
*** haleyb has joined #openstack-infra14:35
openstackgerritValentina Krasnobaeva proposed openstack/project-config master: zuul.d/projects.yaml: remove x/networking-6wind entry  https://review.opendev.org/71141914:35
*** jamesmcarthur has joined #openstack-infra14:35
openstackgerritValentina Krasnobaeva proposed openstack/project-config master: zuul.d/projects.yaml: remove x/networking-6wind entry  https://review.opendev.org/71141914:35
*** ociuhandu has quit IRC14:38
*** ahosam has quit IRC14:38
*** cgoncalves has quit IRC14:39
*** cgoncalves has joined #openstack-infra14:40
*** jamesmcarthur has quit IRC14:41
*** jcapitao has quit IRC14:42
*** jamesmcarthur has joined #openstack-infra14:42
*** jcapitao has joined #openstack-infra14:44
*** haleyb is now known as haleyb|away14:50
*** jamesmcarthur has quit IRC14:58
openstackgerritMonty Taylor proposed openstack/project-config master: Run openstacksdk functional jobs on ansible 2.8 and 2.9  https://review.opendev.org/71147414:58
*** jamesmcarthur has joined #openstack-infra14:58
corvusbrtknr: i don't believe any of our current nodesets have gpus; out of curiosity, what do you need them for?15:03
*** ociuhandu has joined #openstack-infra15:07
*** gfidente has quit IRC15:08
AJaegerinfra-root, could you review some of the Infra Manual changes for OpenDev, please? https://review.opendev.org/#/q/project:openstack/infra-manual+is:open15:09
mordredcorvus, brtknr: I agree, I do not believe we have any - but I think at least vexxhost has that ability and I seem to remember that mnaser has provided some nodes to another project?15:11
*** hashar has quit IRC15:16
fungimnaser did ask at one point if we wanted some gpu flavors to try stuff out15:16
fungino idea if that offer still stands15:16
AJaegerthanks, corvus !15:17
AJaegerI think we got to nodes from mnaser , looking at project-config/nodepool15:18
AJaegerto -> two nodes15:18
*** jaosorior has quit IRC15:20
*** ramishra has quit IRC15:21
openstackgerritMerged openstack/infra-manual master: Move CLA section to contributor guide  https://review.opendev.org/71128615:22
openstackgerritMerged openstack/infra-manual master: opendev: Update index page  https://review.opendev.org/71130215:22
openstackgerritMerged openstack/infra-manual master: Cleanup Gerrit Approval event note  https://review.opendev.org/71130315:22
*** ramishra has joined #openstack-infra15:23
openstackgerritMerged openstack/infra-manual master: Update core.rst for two +2 policy  https://review.opendev.org/71132915:23
openstackgerritMerged openstack/infra-manual master: opendev: Update irc.rst  https://review.opendev.org/71130615:23
mnaserWe can provide them but they are very limited.15:23
*** jamesmcarthur has quit IRC15:23
mnaserThey’re super pricey :)15:23
openstackgerritMerged openstack/infra-manual master: Remove python manual page  https://review.opendev.org/71130815:24
openstackgerritMerged openstack/infra-manual master: Update sandbox for OpenDev  https://review.opendev.org/71131215:24
openstackgerritMerged openstack/infra-manual master: Update testing for OpenDev  https://review.opendev.org/71131315:24
openstackgerritMerged openstack/infra-manual master: Improve job naming convention docs  https://review.opendev.org/71132115:24
openstackgerritMerged openstack/infra-manual master: Point to Zuul docs for configuring jobs  https://review.opendev.org/71132515:24
openstackgerritMerged openstack/infra-manual master: Update python files for OpenDev  https://review.opendev.org/71132315:24
corvusAJaeger: mostly +3s and 2 -1s :)15:24
AJaegerboth helps ;)15:26
fungimnaser: yeah, we haven't previously had anyone ask for gpu nodes either, so it doesn't seem particularly in demand for opendev15:26
corvusclarkb, mordred: topic:container-requires is ready when you have a minute -- i've rerun the tests after the base-jobs change merged and they're all clear (we can ignore the storyboard unit test failure)15:26
AJaegerthanks, corvus15:26
*** jamesmcarthur has joined #openstack-infra15:27
*** jamesmcarthur has quit IRC15:36
openstackgerritJames E. Blair proposed openstack/project-config master: Run openstacksdk functional jobs on ansible 2.8 and 2.9  https://review.opendev.org/71147415:37
openstackgerritAndreas Jaeger proposed openstack/infra-manual master: Rework README.rst for OpenDev  https://review.opendev.org/71132415:37
corvusmordred: ^ you spelled "openstacksdk" as "shade" :)15:37
mordredcorvus: haha15:38
openstackgerritAndreas Jaeger proposed openstack/infra-manual master: OpenDev Update for Creator's Guide  https://review.opendev.org/71141115:38
AJaegercorvus: great feedback, I pushed updates15:39
corvuslogan-: the limestone mirror, 25c4df93-bcf5-460c-948a-bb66bb4b177b has been in reboot state for ~24 hours -- should we rebuild the server?15:40
corvusinfra-root: ^ fyi15:40
fricklercorvus: do we have any other contact for limestone? otherwise I'd agree we should simply rebuild it15:42
corvusAJaeger: lgtm!15:42
AJaegerthanks15:42
mordredcorvus: in https://review.opendev.org/#/c/710116/2/.zuul.yaml ...15:43
corvusfrickler: i'm unaware of other contacts15:43
mordredzuul is in the zuul tenant, but the python-base and python-builder images are built in the openstack tenant - will those requires ever be meanigful?15:44
corvusmordred: nope, but i'd like to leave them there anyway15:44
mordredkk15:44
corvusthey don't hurt, and they're future-compatible with anything we might do to change that15:44
corvusmordred: if you want, we can add a comment saying they are currently noops15:45
*** jamesmcarthur has joined #openstack-infra15:45
*** jamesmcarthur has quit IRC15:45
mordrednah - mostly just double-checking my understanding15:45
*** jamesmcarthur has joined #openstack-infra15:45
corvusk15:45
*** ramishra has quit IRC15:48
openstackgerritFelix Edel proposed zuul/zuul master: Provide some documentation for the checks API implementation  https://review.opendev.org/71149315:55
*** ociuhandu has quit IRC15:55
*** jcapitao is now known as jcapitao_afk15:56
*** ociuhandu has joined #openstack-infra15:57
openstackgerritFelix Edel proposed zuul/zuul master: Make github file annotation levels configurable via zuul return  https://review.opendev.org/71117915:58
*** ociuhandu has quit IRC16:02
*** ociuhandu has joined #openstack-infra16:02
openstackgerritMerged openstack/infra-manual master: OpenDev Update for Creator's Guide  https://review.opendev.org/71141116:06
openstackgerritMerged openstack/infra-manual master: Rework README.rst for OpenDev  https://review.opendev.org/71132416:06
openstackgerritMerged openstack/infra-manual master: List other Contributor Guides  https://review.opendev.org/71139316:06
fungii need to go run some post-travel lunch errands but hope to start catching up this afternoon... bbiaw16:07
*** jcapitao_afk is now known as jcapitao16:10
*** mattw4 has joined #openstack-infra16:11
*** jcapitao has quit IRC16:12
openstackgerritFelix Edel proposed zuul/zuul master: Dequeue changes via github checks API  https://review.opendev.org/70913516:16
*** jcapitao has joined #openstack-infra16:18
mordredcorvus: would you learn me something real quick?16:18
*** gyee has joined #openstack-infra16:18
mordredcorvus: in zuul/zuul - there is no explicit mention of opendev-buildset-registry - that's because build-image is, itself, a buildset-registry right?16:18
mordredcorvus: but in system-config, we have an explicit opendev-buildset-registry job and dependencies on opendev-buildset-registry16:19
*** KeithMnemonic1 has joined #openstack-infra16:19
mordredI think I'm still on first coffee - but my brain is refusing to tell me why one vs the other approach should be used16:20
corvusmordred: if 2 or more jobs in a project require a buildset registry, use an explicit registry job16:21
corvus(that way they all share a registry)16:22
*** Lucas_Gray has joined #openstack-infra16:23
*** KeithMnemonic has quit IRC16:23
*** eharney has quit IRC16:25
mordredcorvus: nod. so in zuul/zuul's case the only job we have using the registry is the quick-start16:26
AJaegerclarkb: all changes for the infra manual are merged thanks to corvus and mordred, check https://docs.openstack.org/infra/manual/ for current update.16:27
corvusmordred: yep16:28
mordredcorvus: nod16:28
corvusmordred: it's probably not required -- i think we could have each job in system-config run its own registry and be fine.  just seemed easier to think about.16:28
mordredcorvus: I updated  remote:   https://review.opendev.org/711246 Build utility image for using osc  with the new specific provides/requires stuff - look ok to you?16:29
*** jcoufal has quit IRC16:29
*** pgaxatte has quit IRC16:31
*** ramishra has joined #openstack-infra16:33
*** aedc_ has joined #openstack-infra16:34
clarkbAJaeger: mordred corvus thank you! bit of a dlow start today but almost ready to dig into the job deps/requires stuff16:36
*** aedc has quit IRC16:36
*** zxiiro has joined #openstack-infra16:39
openstackgerritAndreas Jaeger proposed openstack/infra-manual master: Update "Outbound Third-Party Testing" for OpenDev  https://review.opendev.org/71150816:41
openstackgerritAndreas Jaeger proposed openstack/infra-manual master: Update "Outbound Third-Party Testing" for OpenDev  https://review.opendev.org/71150816:42
*** udesale has quit IRC16:44
corvusmordred: lgtm!16:45
mordredcorvus: cool!16:45
*** ccamacho has quit IRC16:48
*** aedc_ has quit IRC16:49
*** aedc_ has joined #openstack-infra16:51
clarkbcorvus: I've approved all but https://review.opendev.org/#/c/710117/1 which needs its depends on to land first. I'm going to find breakfast but if those other changes land more quickly feel free to approve. I'll try to get it otherwise16:52
*** matt_kosut has joined #openstack-infra16:52
corvusclarkb: thanks, i can take care of the +W16:52
*** ociuhandu_ has joined #openstack-infra16:54
openstackgerritAndreas Jaeger proposed openstack/infra-manual master: Update "Code Review" for OpenDev  https://review.opendev.org/71151416:54
*** rcernin has quit IRC16:55
*** aedc_ has quit IRC16:56
*** ociuhandu has quit IRC16:58
*** ociuhandu_ has quit IRC16:59
*** tesseract-RH has quit IRC17:01
clarkbmnaser: AJaeger brtknr mordred to be clear we still have the vexxhost gpu flavors enabled in nodepool17:09
clarkbcorvus: can you rereview https://review.opendev.org/#/c/711344/ now that it passes testing (to get the lodgeit stuff moving)17:10
*** jackedin has joined #openstack-infra17:10
clarkbcorvus: https://review.opendev.org/#/c/711345/2 too17:10
openstackgerritClark Boylan proposed opendev/puppet-httpd master: Define params::ssl_path for vhost::proxy  https://review.opendev.org/71136517:14
openstackgerritClark Boylan proposed opendev/puppet-httpd master: Fix leading :: on class includes to make linter happy  https://review.opendev.org/71151717:14
corvusclarkb: +3.  i'm still unclear about whether we should be careless or careful approving changes, but i'll just follow mordred's lead on that ;)17:16
mordredcorvus: I think we should be lessful17:17
clarkbcorvus: we can let zuul be careful then we can be careless17:17
mordredclarkb: ++17:17
clarkbhttps://review.opendev.org/711365 and https://review.opendev.org/711517 are related as I discovered an error in the server's puppet logs when looking at this yesterday17:17
openstackgerritMerged opendev/storyboard master: Use explicit provides/requires for container jobs  https://review.opendev.org/71011317:17
*** matt_kosut has quit IRC17:18
*** jamesmcarthur_ has joined #openstack-infra17:21
*** igordc has joined #openstack-infra17:22
*** jamesmcarthur has quit IRC17:24
*** matt_kosut has joined #openstack-infra17:25
*** rpittau is now known as rpittau|afk17:25
*** jackedin has quit IRC17:30
clarkbmordred: corvus https://review.opendev.org/#/c/710885/ is related to testing with containers in system-cofnig land. I think both ianw and i have run into separate issues there17:31
clarkbbut I think that change addresses those issues if you have a chance to look at it17:31
clarkbIn other news we expect the airship citycloud kna region to be more reliable ~tomorrow17:31
clarkbapparently they had pulled hypervisors out for hardware issues and that was causing the scheduling erorrs17:31
*** eharney has joined #openstack-infra17:31
clarkbif it doesn't get better in the near future the frankfurt region has been suggested as an alternative option17:32
*** ociuhandu has joined #openstack-infra17:32
*** evrardjp has quit IRC17:35
*** evrardjp has joined #openstack-infra17:35
*** ociuhandu has quit IRC17:36
fungiand if we need to send some folks to frankfurt, say around oktoberfest, i'm happy to volunteer17:39
*** dtantsur is now known as dtantsur|afk17:40
openstackgerritMerged zuul/nodepool master: Use explicit provides/requires for container jobs  https://review.opendev.org/71011517:46
openstackgerritJames E. Blair proposed ttygroup/gertty master: Fix error in message refresh  https://review.opendev.org/71152317:49
openstackgerritMerged opendev/system-config master: Use explicit provides/requires for container jobs  https://review.opendev.org/71010617:50
openstackgerritMerged opendev/puppet-lodgeit master: Allow pinning the lodgeit version  https://review.opendev.org/71134417:50
openstackgerritMerged opendev/system-config master: Pin lodgeit to the current version  https://review.opendev.org/71134517:50
*** derekh has quit IRC18:00
mordredwoot18:01
mordredclarkb: https://review.opendev.org/#/c/684783/ should be safe to revie wnow18:03
corvuswould it be a good idea to make all pastes private?18:08
*** matt_kosut has quit IRC18:08
clarkbcorvus: you mean using the randomized url pattern?18:09
corvusyep18:09
clarkbthat may help deter the spammers, I would not be opposed18:09
corvuswell, i dunno if it would or not, but i mostly don't see the value in being able to see pastes by guessing urls18:09
*** jcapitao is now known as jcapitao_off18:10
fungithe main thing that does is get rid of folks enumerating paste index numbers to find what's in them18:10
*** jamesmcarthur_ has quit IRC18:10
fungii don't know that it does anything to deter spammers putting things in pastes18:10
fungiwe set robots.txt to tell search engines not to index anything there anyway18:10
openstackgerritMerged opendev/lodgeit master: Update URLs from openstack.org to opendev.org  https://review.opendev.org/66647518:10
corvusright.  my thought is it might save someone embarassment some day18:11
fungiyeah, for the record, i'm cool with it18:11
*** slaweq has joined #openstack-infra18:11
fungijust saying i don't think it's a spam mitigation mechanism18:12
openstackgerritMerged opendev/system-config master: Collect docker logs as root  https://review.opendev.org/71088518:12
fungi(it certainly has other useful properties, such as pastes becoming private until you share their urls)18:12
*** kaisers1 has quit IRC18:15
*** jcapitao_off has quit IRC18:15
*** chandankumar is now known as raukadah18:18
*** ccamacho has joined #openstack-infra18:20
*** Goneri has quit IRC18:23
logan-o/ noticed the limestone mirror had some issues yesterday. i'll look into that sometime before eow, but initially it looks like the compute node hosting the mirror is down. will update once I have a better idea of what the status is with it.18:26
*** jpena is now known as jpena|off18:26
*** Goneri has joined #openstack-infra18:27
clarkbmordred: I believe https://review.opendev.org/#/c/684783/8/scripts/lodgeit.py has a bug in it. Details all in the change18:28
*** kaisers has joined #openstack-infra18:31
*** mattw4 has quit IRC18:32
fungithanks for taking a look logan-!18:32
*** mattw4 has joined #openstack-infra18:32
*** Lucas_Gray has quit IRC18:34
*** eharney has quit IRC18:34
*** amoralej is now known as amoralej|off18:35
openstackgerritAndreas Jaeger proposed openstack/infra-manual master: Shrink "Peer Review" section  https://review.opendev.org/71153018:36
AJaegerthis is now a very brief "Peer Review" section, please do a peer review ^18:37
*** mattw4 has quit IRC18:37
AJaegerconfig-core, two repos need their py27 jobs removed: https://review.opendev.org/711419 and https://review.opendev.org/711399 . Please review18:38
*** mattw4 has joined #openstack-infra18:38
*** diablo_rojo has quit IRC18:40
*** diablo_rojo has joined #openstack-infra18:42
*** hashar has joined #openstack-infra18:46
*** slaweq has quit IRC18:47
openstackgerritMerged openstack/project-config master: zuul.d/projects.yaml: remove x/networking-6wind entry  https://review.opendev.org/71141918:49
clarkbmordred: have a moment for https://review.opendev.org/#/c/711365/2 and its parent (related to lodgeit puppet)18:50
openstackgerritMerged openstack/project-config master: Remove networking-zvm entry  https://review.opendev.org/71139918:51
mordredclarkb: ffs. I'm pretty sure we put :: on the front of those a while back to make a linter happy18:52
clarkbmordred: I think it was requiredin puppet 3 but then puppet 4 unrequired it. Then the linters in their infinite wisdom felt that meant you must now change it all again18:53
clarkbrather than "yay puppet made our lives easier cool" and leaving it at that18:53
fungii think this just reminds us we're past due to rip out puppet18:53
clarkbgmann: I keep meaning to respond to your question about who should maintain e-r18:54
openstackgerritAndreas Jaeger proposed openstack/infra-manual master: Remove "Eligibility to Vote in Elections" section  https://review.opendev.org/71153218:55
clarkbgmann: I think e-r is an excellent tool and it would be great to make it a bit more generic (basically split out the input queries into config and not in the main repo and probably stuff in the UI) so that more than just openstack can feel like they can use it18:55
clarkbgmann: I know I don't really have time for that right now with all the other opendev stuff happening, but if that is something the qa team t hinks would also be useful I'd be happy to have them be more involved18:55
*** gshippey has quit IRC18:55
AJaegerclarkb: IMHO now comes the tricky part with the infra manual, I'm therefore tackling section by section as you might have noticed...18:57
*** ralonsoh has quit IRC18:57
openstackgerritMerged openstack/infra-manual master: Shrink "Peer Review" section  https://review.opendev.org/71153018:58
AJaegerclarkb: there're some parts I'm not sure about yet as well ;)18:58
clarkbAJaeger: ya I think we can take our time with the tricky parts and review them and make sure they make sense18:59
AJaegerclarkb: indeed. I'll think I'll take now an "easy" iteration next...19:00
gmannclarkb: yeah that is what I assumed. it is good to make it generic and moving openstack queries under separate config. I think it can be moved to opendev as it is and start improving. or you think we need to  make it generic first from opendev point of view ?19:00
clarkbgmann: I don't think we have to make it generic first. I'm mostly just concerned wtih having an agreed upon plan is we are going to recruit new contributors19:00
clarkb(that way everyone agrees on some high level goals)19:01
gmannok19:02
clarkbgmann: I think the top priority outside of simply maintaining the queries is to split the query set off into a config file/dir/repo19:02
*** larainema has quit IRC19:03
clarkbwe've also got a bug where it OOMs itself if the query result is too large so throttling that somehow would be good19:03
clarkband then maybe update the UI to be multi tenant19:03
clarkb(so we don't have to run multiple UI instances)19:03
*** harlowja has joined #openstack-infra19:04
mordredI think I have a shwarma deficiency that needs to be fixed19:05
clarkbI didn't realize I had a shwarma deficiency until just now19:05
clarkbwhich has quickly become a tacos al pastor deficiency19:06
AJaegerI'm sure I have a shwarma deficiency - since I never heard about that word before ;)19:06
clarkbAJaeger: Doner kebab is a derivative iirc19:07
clarkb(as is tacos al pastor)19:07
AJaegerclarkb: you mean Shawarma? Or is that now written shwarma?19:07
mordredyes. I just can't spell19:07
mordredhttps://en.wikipedia.org/wiki/Shawarma19:07
AJaegerall good, thanks ;)19:08
*** jaosorior has joined #openstack-infra19:08
openstackgerritAndreas Jaeger proposed openstack/infra-manual master: Update Driver's Guide for OpenDev  https://review.opendev.org/71153419:19
openstackgerritAndreas Jaeger proposed openstack/infra-manual master: Update Developer's Guide for OpenDev  https://review.opendev.org/71153619:32
AJaegerclarkb, infra-root, enough infra-manual for me for today. Reviews or followup work welcome as usual ;)19:32
openstackgerritMerged opendev/puppet-httpd master: Fix leading :: on class includes to make linter happy  https://review.opendev.org/71151719:37
openstackgerritMerged opendev/puppet-httpd master: Define params::ssl_path for vhost::proxy  https://review.opendev.org/71136519:37
*** ijw has quit IRC19:37
*** eharney has joined #openstack-infra19:48
openstackgerritAndreas Jaeger proposed openstack/infra-manual master: Update Developer's Guide for OpenDev  https://review.opendev.org/71153619:49
clarkbI settled for breakfast tacos as I had that at home19:54
mordredclarkb: not the ones that were sitting under the couch I hope19:55
clarkbmordred: no eggs and sausage were cooked19:56
mordredmmm19:56
mordredI went to Shawarma on the Go - which is located in a gas station - and is brilliant19:56
clarkbmordred: did you see then ote on the lodgeit python3 change? I want to make sure I'm not wrong there and maybe we can just update the change?19:56
mordredclarkb: I thnik you are right - and I also think it's ok it's just a utility not part of the code ... but we could also just update it like you mention20:02
mordred(I mean it's ok if we wanted to just do a followup)20:03
clarkboh I see20:04
clarkbya if its not part of the webserving I can go ahead and approve then push a followup20:04
clarkbah its the pasting script so ya20:05
clarkbmordred: I went ahead and approved. Working on a followup now20:06
mordredcool. good catch on that20:08
*** matt_kosut has joined #openstack-infra20:09
*** ociuhandu has joined #openstack-infra20:09
openstackgerritClark Boylan proposed opendev/lodgeit master: Fix sort comparison function  https://review.opendev.org/71154420:10
clarkbmordred: ^ there20:10
mordred+220:10
*** ijw has joined #openstack-infra20:11
openstackgerritMerged opendev/lodgeit master: Fix python3 compatibility issue  https://review.opendev.org/68478320:12
*** matt_kosut has quit IRC20:13
*** ociuhandu has quit IRC20:25
openstackgerritMerged zuul/zuul master: Don't rely on report-build-page when building the buildset result url  https://review.opendev.org/71140620:28
openstackgerritMerged zuul/zuul master: Use explicit provides/requires for container jobs  https://review.opendev.org/71011620:28
*** ociuhandu has joined #openstack-infra20:28
clarkbAJaeger: left a couple of notes on https://review.opendev.org/#/c/711536/2 for tomorrow20:30
openstackgerritAndreas Jaeger proposed openstack/infra-manual master: Update Developer's Guide for OpenDev  https://review.opendev.org/71153620:32
AJaegerclarkb: thanks, updated20:32
clarkbI'll do a followup for the draft disablement20:34
AJaegercool20:34
openstackgerritClark Boylan proposed openstack/infra-manual master: Document why drafts are disabled  https://review.opendev.org/71155020:36
*** trident has quit IRC20:37
clarkbthat might be overly verbose20:37
*** ociuhandu has quit IRC20:37
*** ociuhandu has joined #openstack-infra20:38
AJaegerclarkb: let me do a small edit...20:39
openstackgerritAndreas Jaeger proposed openstack/infra-manual master: Document why drafts are disabled  https://review.opendev.org/71155020:42
clarkbwfm20:43
*** ociuhandu has quit IRC20:43
*** trident has joined #openstack-infra20:47
*** hashar has quit IRC20:48
*** sshnaidm is now known as sshnaidm|afk20:48
*** slaweq has joined #openstack-infra20:48
*** rcernin has joined #openstack-infra20:53
*** cgoncalves has quit IRC20:53
AJaegerteam, we broke the upstream-translation-update job, see http://zuul.opendev.org/t/openstack/builds?job_name=upstream-translation-update20:56
AJaeger"The task includes an option with an undefined variable. The error was: 'afs' is undefined20:56
*** cgoncalves has joined #openstack-infra20:56
AJaegercould somebody look into that, please? I guess its a fallout from the static.o.o cleanups...20:57
clarkbwhats the need for afs in translation jobs?20:57
clarkbI'll look20:57
AJaegerclarkb: we upload the files to tarballs.o.o, maybe we forgot about that?20:57
clarkbah that could be20:58
*** jamesmcarthur has joined #openstack-infra20:59
AJaeger playbooks/publish/openstack-artifacts.yaml is a post-run playbook, guess that fails20:59
AJaegersorry, have to leave now... thanks, clarkb20:59
AJaegerbroken between 12th and 18th of February, according to http://zuul.opendev.org/t/openstack/builds?job_name=upstream-translation-update&project=openstack%2Fkeystone21:01
clarkbAJaeger: https://review.opendev.org/#/c/706734/2/zuul.d/jobs.yaml that change21:03
clarkbnow that we know why it broke we can add back in the necessary secret I'll try to figure that out21:03
corvusftr, i'm looking into this too, but it's complicated, so i think it's good for both clarkb and i to dig into it21:03
AJaegerclarkb: that merged on the 20th, but keystone failed already on the 18th21:04
AJaegerthanks, corvus21:04
*** nicolasbock has quit IRC21:05
clarkbhttps://opendev.org/openstack/project-config/src/branch/master/playbooks/publish/openstack-artifacts.yaml#L12 is where that role is trying to write to21:06
clarkbbut https://tarballs.opendev.org/openstack/translation-source/ is where we want to write to21:06
corvusclarkb: i think it's the cerate afs token above that which is failing21:06
clarkbcorvus: ya, I'm just noting that if we fix that we'll start doing the wrong thing21:07
corvusoh21:07
corvuswhere should they go?21:07
*** xek_ has quit IRC21:07
corvusoh nm, i just missed your second msg21:07
clarkbcorvus: they go in https://tarballs.opendev.org/openstack/translation-source/$PROJECT_NAME21:07
clarkbI think we can address that with a different playbook for translations21:08
clarkblet me try mock some of this up (annd I'm sure it will need modification)21:08
openstackgerritAndreas Jaeger proposed openstack/project-config master: Fix openstack-manuals sync  https://review.opendev.org/71155421:08
*** cgoncalves has quit IRC21:10
openstackgerritClark Boylan proposed openstack/project-config master: Fix afs publishing of translation sources  https://review.opendev.org/71155521:11
clarkbAJaeger: corvus ^ I don't know that that is complete or correct but is what I've found so fafr21:11
*** cgoncalves has joined #openstack-infra21:11
AJaegerclarkb: https://review.opendev.org/#/c/706733/ is the change that introduced it and broke it, so same file...21:12
corvusclarkb: i think that would work -- it's worth a check of the other playbooks in that job to make sure that they're safe for the afs secret, but they already have the zanata secret, so hopefully so21:13
corvusclarkb: i also left a comment21:14
clarkbcorvus: ya and that job used an afs secret before so should be ok I think, will skim21:14
corvusclarkb: i don't think it used any other secret before; it relied on the fileserver ssh key secret in its parent21:15
AJaegerclarkb: thanks, nearly perfect ;)21:15
clarkbcorvus: oh sorry it used the fileserver secreet https://review.opendev.org/#/c/706734/2/zuul.d/jobs.yaml21:16
clarkbcorvus: that was ssh not afs21:16
*** jamesmcarthur has quit IRC21:16
corvusclarkb: yep, sorry, you're right it did use a secret, and it was the ssh key21:16
corvusso this is pretty close to the same approach we had before, we're just doing the path change by forking the playbook rather than trying to have a variable for both21:16
corvusclarkb: i've skimmed the playbooks, and i don't see anything jump out at me21:17
*** jamesmcarthur has joined #openstack-infra21:18
corvusclarkb: so i think if you take care of the 2 comments, that change is gtg21:18
clarkbcorvus: ya seems to install tools that it needs (sphinx babel and our local scripts for interacting with zanta), then runs the zanata interaction, fetches the translations to the executor then copies to tarballs21:18
*** exsdev0 has joined #openstack-infra21:18
corvusyep.  the zanata script is controlled, and we're not running a sphinx build or anything21:18
*** rcernin has quit IRC21:18
*** eharney has quit IRC21:18
*** dpawlik has quit IRC21:18
openstackgerritClark Boylan proposed openstack/project-config master: Fix afs publishing of translation sources  https://review.opendev.org/71155521:19
corvus(a sphinx build could execute code to dump the cred, so that's something to watch out for)21:19
AJaegerwhen you're reviewing, have a look at 711554 as well, simple typo that broke another job - I checked openstack-manuals post jobs and both where broken ;(21:19
*** exsdev has quit IRC21:19
AJaeger(translation was the other one), please21:19
*** exsdev0 is now known as exsdev21:19
clarkbdid fungi write that from baston?21:19
clarkb:)21:19
ianwmordred: if around would you mind looping back to the LE account email stack @ https://review.opendev.org/#/c/711149 ; addressed your comments21:20
fungiclarkb: write what?21:20
clarkbfungi: 'taget' instead of 'target'21:20
* fungi wrote very little from the boston bastion21:20
fungiitym taahget21:21
clarkbright that :)21:21
corvusoh man you are not sending me to my happy place21:21
corvusthough i do kinda want to listen to old car talk episodes now21:22
AJaegercorvus: the translation job runs sphinx-build, see https://opendev.org/openstack/openstack-zuul-jobs/src/branch/master/roles/prepare-zanata-client/files/common_translation_update.sh#L42621:22
fungithe car talk guys were (are?) awesome21:23
corvusfungi: 'were' these days :(21:23
corvusAJaeger: but that's distinct from the update job, yeah?21:23
fungier, i meant to say, "wicked awesome" sorry21:24
corvusfungi: ray is still alive, but is decidedly retired, tom died a few years back21:25
AJaegercorvus: I think that's run in the job we looked at21:25
fungi:(21:25
clarkbAJaeger: corvus https://opendev.org/openstack/openstack-zuul-jobs/src/branch/master/roles/prepare-zanata-client/files/upstream_translation_update.sh#L115-L117 it is if there are sphinx docs21:25
clarkb(thats the script run by the upstream-translation job)21:25
clarkbis the gettext command safe though? since that isn't compiling the actual docs21:26
clarkb(But I don't know)21:26
corvusclarkb, AJaeger: oh "neat"21:26
clarkbhttps://www.sphinx-doc.org/en/master/man/sphinx-build.html#cmdoption-sphinx-build-b ya that is what it is doing, not sure yet of side effects21:27
clarkbthe paragraphs at the top there imply that conf.py is evaluated though (which would be dangerous021:27
ianwcomputer hardware specialist : c. colin backslash21:28
mordredianw: is the secret in place already?21:28
corvusclarkb, AJaeger: we may want an extra job layer then....21:29
ianwmordred: no but if you're happy with the approach i can add it now21:29
mordredyeah - I think it looks good!21:29
AJaegercorvus: good that you've asked ;)21:29
corvusclarkb, AJaeger: though, i don't immediately have a way to exploit this21:30
* AJaeger removed the +A from 71155521:30
mordredianw: you might want to see frickler's comment on https://review.opendev.org/#/c/711137/7/doc/source/letsencrypt.rst@14721:30
clarkbI've WIP'd the change, while we sort out the risk21:30
corvusthe secret shouldn't be written out anywhere yet, it only is written (later) on the executor, and something running in conf.py on a remote node shouldn't be able to spawn a process on the executor to watch for the keytab to show up.21:31
* AJaeger really needs to sign off, will read backscroll tomorrow. Thanks!21:31
corvusAJaeger: thanks!21:31
clarkbcorvus: I guess we have to confirm then that the keytab isn't used on the remote host?21:31
clarkbcorvus: because I agree, I think the risk is having conf.py fork and poll for the data to show up (then email it or whatever)21:31
corvusclarkb: https://opendev.org/openstack/project-config/src/branch/master/playbooks/publish/openstack-artifacts.yaml#L12 is 'hosts: localhost'21:31
clarkbbut if the data is never written to the remote I think we are safe21:32
clarkbcorvus: ah right and the run.yaml copies the data to the executor21:32
clarkbso ya I think its ok21:32
corvusclarkb: yeah.  and we're not like passing ansible vars as env vars to the sphinx executable.21:32
corvusclarkb: so i think it's okay.  but the extra scrutiny was warranted.21:33
ianwmordred: ok, will fix after school run21:33
ianwmordred: if you're still in a reviewing mode; https://review.opendev.org/#/q/status:open+project:opendev/system-config+branch:master+topic:nodepool-legacy is a small stack to get a containerised nodepool-builder21:33
clarkbcorvus: alright I'm removing the -W now21:33
clarkbcorvus: do you want to approve or should I?21:33
ianwtop patch is wip but actually i think works now (will re-run and see if we get the docker logs with the root change)21:33
ianws/docker/podman/21:33
corvusclarkb: done21:33
*** slaweq has quit IRC21:33
ianwmordred: largely based upon your prior work with review-dev, so any refactoring comments etc welcome21:34
openstackgerritMerged opendev/base-jobs master: Remove docker-image provides/requires  https://review.opendev.org/71011721:39
mordredianw: cool!21:41
*** michael-beaver has joined #openstack-infra21:42
openstackgerritIan Wienand proposed opendev/system-config master: letsencrypt: add note on manual refresh of certificates  https://review.opendev.org/71113721:50
openstackgerritMerged openstack/project-config master: Fix afs publishing of translation sources  https://review.opendev.org/71155521:56
*** mattw4 has quit IRC22:04
*** mattw4 has joined #openstack-infra22:04
openstackgerritMerged openstack/project-config master: Fix openstack-manuals sync  https://review.opendev.org/71155422:04
*** imacdonn has quit IRC22:04
*** imacdonn has joined #openstack-infra22:05
*** iurygregory has quit IRC22:18
openstackgerritMerged opendev/system-config master: letsencrypt: Register email with accounts  https://review.opendev.org/71113322:23
corvusinfra-root: does this still exist?  https://docs.openstack.org/infra/system-config/certificate_authority.html22:30
*** matt_kosut has joined #openstack-infra22:30
mordredcorvus: doesn't appear to22:31
fungii don't believe so22:31
clarkbthat might be something that wasn't properly migrated from the old host?22:31
fungistruggling to remember what it was even used for22:31
corvuswe are, however, using ssl certs with gearman22:31
fungioh, maybe that was it22:32
clarkbfungi: ^ it was gearman iirc22:32
fungiyeah, i faintly recall that22:32
corvuswe send decrypted secrets over the wire via that22:32
corvusok.  well, docs should stay, and i guess next time we need to do that, we can just recreate it :)22:33
ianwor use LE?22:33
mordredcorvus: should we just use LE?22:33
funginoted22:33
clarkbcan you use LE to sign client certs?22:33
mordredI don't know22:33
clarkbin this case its doing mutual auth22:33
* fungi hears an le chorus in three-part harmony22:33
corvusi do not understand how to use le for this; does someone here know that?22:33
clarkband I thought that was basically a "is your cert signed by the authority I expect"22:33
clarkbI think with LE that would mean any LE cert could auth and that is undesireable22:34
clarkb(I'm happy to be wrong on that though)22:34
mordredthe internet says we cannot use LE for this22:34
fungii suspect if that's the only use case, self-signed certs would also work and be simpler?22:34
corvus(it's unclear to me whether "or use LE?" is "corvus, i think you could use LE, why don't you want to use that?" or "corvus, i don't know if this is relevant, but have you thought about using LE?"22:35
mordredfor the reason that clarkb just said22:35
*** matt_kosut has quit IRC22:35
mordredcorvus: from me it was the second - and now that I've asked I have come to believe that thinking about LE for this use case instead is a Bad Idea22:35
mordredso I'm back around to being ++ on "corvus>ok.  well, docs should stay, and i guess next time we need to do that, we can just recreate it :)"22:36
corvusmordred: ack22:37
corvusi'll think about whether the same restrictions apply to zk22:37
mordredcorvus: I thnik they might for the quorum tls - but I admittedly have only read those docs once22:38
corvusmordred: yeah, that's the impression i'm getting22:39
mordredcorvus: there'sa. lot of java words in those docs22:39
mordredbut I think I'm parsing and translating them right22:39
ianwyeah i'd have to look into it, but it seems you could authenticate the remote side had authenticated it's dns name; which i have a feeling might be enough22:39
corvusmordred: yeah, it's not easy.22:39
corvusianw: that means we'd be trusting reverse dns (which some clouds don't even provide) for authentication22:40
corvus(in order for the server to verify a client)22:41
corvus(plus, i don't think geard actually does that)22:41
corvusso, without modification to geard, the most we could do is say that any LE cert is allowed to be a client of zuul's gearman22:42
corvusand i don't think that's desirable22:42
ianwcorvus: i'm just throwing ideas here, because i don't know.  just in theory, if you trust "gearman01.x.com" and you're presented with a cert signed by LE with that covers that domain, then that host must have either validated itself as such, or somehow otherwise got that certificate22:42
corvusianw: oh, sure, we could modify geard to take a whitelist of certs22:43
corvusbut, believe it or not, geard is mostly compatible with gearmand at this point, i don't think that's worth forking over22:43
clarkbI'm popping out for a bike ridrwith that largely settled22:45
*** tkajinam has joined #openstack-infra22:45
corvusalso, x.com takes me back to last century22:45
ianwso it only trusts at a CA level?22:45
corvusianw: yep22:45
openstackgerritMerged opendev/system-config master: letsencrypt: add note on manual refresh of certificates  https://review.opendev.org/71113722:48
ianw"If you are not paying for a certificate authority to generate a certificate for you, you will first need to generated a CA for gearmand: ..." on http://gearman.info/gearmand/ssl.html implies maybe you can use a 3rd party22:48
ianwthat site also doesn't have https ... so ...22:48
openstackgerritIan Wienand proposed opendev/system-config master: ansible-lint : disable 503  https://review.opendev.org/71114922:57
*** mattw4 has quit IRC23:04
*** mattw4 has joined #openstack-infra23:05
*** ociuhandu has joined #openstack-infra23:07
*** rh-jelabarre has quit IRC23:11
*** ociuhandu has quit IRC23:11
*** jamesmcarthur has quit IRC23:14
*** mattw4 has quit IRC23:18
*** mattw4 has joined #openstack-infra23:19
*** jamesmcarthur has joined #openstack-infra23:20
*** dchen has joined #openstack-infra23:22
fungiany reason you can't set each client's cert as a ca too, so that self-signed certs would work? of course you'd need to update the list of trusted authorities each time you added/replaced a client23:24
*** jamesmcarthur has quit IRC23:32
clarkbfungi: I think that would work if you allowed for setting multiple CA23:59

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!